Vehicle security & recovery platform
Last Updated: May 2026 — aligned with current web portal and mobile app data practices
1. Introduction
AutoGuard Pro ("we," "us," or "our") is committed to protecting your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our vehicle security and recovery platform.
This policy complies with the Protection of Personal Information Act (POPIA) of South Africa and other applicable data protection laws.
2. Information We Collect
2.1 Personal Information
What we collect depends on how you use the service:
Web portal registration (fleet managers and brokers) — we collect:
- Identity: Full name (first and last name on the registration form)
- Contact: Email address and phone number
- Organisation: Registered company name, broker code and insurer (where applicable)
- Account credentials: Email (used to sign in) and password (stored encrypted; we never store plain-text passwords)
We do not collect South African ID numbers or dates of birth on the web registration form.
Mobile app and profile — clients and drivers may additionally provide:
- Emergency contact name and phone number
- Medical conditions relevant to emergency response (optional)
- Driver's licence photo (optional, for identification)
- FCM device token for push notifications (mobile app)
2.2 Vehicle Information
When you enroll vehicles, we collect:
- Vehicle Details: Make, model, year, color, license plate number
- Identification Numbers: VIN (Vehicle Identification Number), engine number
- Registration Information: License disk details, registration number
- Photos: Vehicle images for identification purposes
- Tracker Information: Tracker company and tracking numbers
2.3 Location Data
With your consent (mobile app permissions or when you submit a web/mobile incident report), we collect:
- Incident GPS: Coordinates submitted with a panic or incident report
- Incident address: Where you provide a street address or description of the scene
We do not maintain a continuous travel-history log or background route tracking. Location is tied to incidents and service delivery, not general movement profiling.
2.4 Automatically Collected Information
When you use our service, we may automatically collect:
- Security and audit logs: IP address, browser or app user-agent, timestamps, and significant account actions (for fraud prevention and accountability)
- Incident metadata: Report source (web or mobile) and device description where submitted with an incident
- Push notifications: FCM token (mobile) or Web Push subscription endpoint and keys (operator portal, with your browser permission)
- Session storage (web): Non-sensitive UI preferences such as your role label after login — not used for cross-site tracking
2.5 Incident and Emergency Data
When you report an incident, we collect:
- Incident Details: Type of incident, date, time, description
- Emergency Information: Medical conditions, emergency contacts
- Supporting Evidence: Photos, voice notes, witness information
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Service Delivery
- To create and manage your account
- To enroll and manage your vehicles
- To provide real-time monitoring and tracking
- To process and respond to incident reports
- To coordinate with emergency services when needed
3.2 Communication
- To send you service notifications and alerts
- To respond to your inquiries and support requests
- To notify you of account approvals or status changes
- To send security updates and important notices
3.3 Security and Safety
- To detect and prevent fraud or unauthorized access
- To verify your identity and authenticate access
- To investigate suspicious activity or policy violations
- To protect the rights and safety of our users and others
3.4 Legal and Compliance
- To comply with legal obligations and law enforcement requests
- To maintain records as required by law
- To enforce our Terms of Service
3.5 Service Improvement
- To analyze usage patterns and improve our services
- To develop new features and functionality
- To conduct research and generate anonymized statistics
4. Legal Basis for Processing (POPIA)
Under POPIA, we process your personal information based on the following grounds:
- Consent: You have given explicit consent for specific purposes
- Contract: Processing is necessary to fulfill our service agreement with you
- Legal Obligation: Processing is required by law
- Legitimate Interest: Processing is necessary for our legitimate business interests
- Vital Interests: Processing protects your vital interests or those of another person (emergency situations)
5. Information Sharing and Disclosure
We may share your information with the following parties:
5.1 Emergency Services
During active emergencies, we may share your information with:
- Police and law enforcement agencies
- Ambulance and medical emergency services
- Fire and rescue services
- Private security and recovery teams
5.2 Service Providers (processors)
We use the following categories of processors to run the platform (contracts and safeguards apply where data leaves South Africa):
- Platform development & support: Impact Elements (Pty) Ltd (South Africa) — software engineering, maintenance, and technical operations under contract with AUTOGUARD PRO (Pty) Ltd
- Hosting: Self-hosted application and database infrastructure (HTTPS in transit)
- Email: SMTP provider (e.g. Brevo) for account and incident notifications
- Mobile push: Google Firebase Cloud Messaging (FCM)
- Web push: Browser push services (operator portal desktop notifications)
- Voice transcription: Groq Whisper and/or Google Cloud Speech-to-Text (when you submit voice notes)
- Messaging: Telegram and/or Twilio WhatsApp for operational alerts (where configured)
5.3 Business Partners
With your consent, we may share information with:
- Insurance companies and brokers
- Tracker companies
- Fleet management partners
5.4 Legal Requirements
We may disclose information when required by law, court order, or government request, or to protect our rights and safety.
6. Data Security
We implement security measures appropriate to the risk, including:
- Encryption in transit: TLS/HTTPS for all production access
- Password protection: Passwords stored using industry-standard hashing (bcrypt)
- Access controls: Role-based access, JWT/httpOnly session cookies, CSRF protection on the web portal
- Audit logging: Significant actions recorded for accountability
- Infrastructure: Hosted on controlled, monitored servers — database and backup encryption should match your deployment standards
7. Data Retention
We retain your personal information for as long as:
- Your account remains active
- Required to fulfill the purposes outlined in this policy
- Required by law or regulatory obligations
- Necessary for legal claims or disputes
After your account is closed (deactivated by an administrator), we retain certain data for up to 5 years for legal and operational purposes, then automatically purge personal data (accounts, uploads, and linked incident records) unless a longer period is required by law.
8. Your Rights (POPIA Data Subject Rights)
You have the following rights regarding your personal information:
8.1 Right to Access
You may request a copy of the personal information we hold about you.
8.2 Right to Correction
You may request correction of inaccurate or incomplete information.
8.3 Right to Deletion
You may request deletion of your personal information, subject to legal retention requirements. Step-by-step instructions (including for Google Play): Request data & account deletion.
8.4 Right to Object
You may object to processing of your information for certain purposes.
8.5 Right to Data Portability
You may request transfer of your data to another service provider.
8.6 Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time.
To exercise these rights, use Download my data on your profile (web portal), submit a request via data deletion, contact [email protected], or call +27 65 074 5023.
9. Cross-Border Data Transfers
Your data may be transferred to and processed in countries outside South Africa. We ensure appropriate safeguards are in place, including:
- Standard contractual clauses
- Adequacy determinations
- Binding corporate rules
10. Children's Privacy
Our service is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors.
11. Cookies and Similar Technologies
The web portal uses only essential technologies — we do not use advertising or third-party analytics cookies.
- Essential session cookies (httpOnly): Keep you signed in securely after login. Required for the service; cannot be disabled while using the portal.
- Local storage: We may store a cookie-notice acknowledgement and a non-sensitive role label in
localStorage / sessionStorage for UI convenience.
- Web Push (optional): Only if you enable desktop notifications on the operator portal — handled by your browser and our push subscription API.
The mobile app uses device permissions (location, notifications, camera) rather than browser cookies; see your device settings to manage those permissions.
You can clear cookies through your browser settings; clearing session cookies will sign you out of the web portal.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform. Your continued use of the service after changes constitutes acceptance of the updated policy.
13. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or your personal information:
- Email: [email protected]
- Information Officer: Charolet Peens — [email protected]
- Phone: +27 65 074 5023
- Address: AUTOGUARD PRO (Pty) Ltd, 51 Union Forest Plantation, Delmas, Mpumalanga, 2210, South Africa
14. Complaints
If you believe your privacy rights have been violated, you may lodge a complaint with the Information Regulator of South Africa: